Severity
9.1CRITICAL
EPSS
3.0%
top 13.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 24

Description

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r62p-gprp-gvww: Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow2022-05-24
CVEList
Cisco Application Policy Infrastructure Controller Command Injection and File Upload Vulnerabilities2021-08-25

📋Vendor Advisories

1
Cisco
Cisco Application Policy Infrastructure Controller Command Injection and File Upload Vulnerabilities2021-08-25
CVE-2021-1581 (CRITICAL CVSS 9.1) | Multiple vulnerabilities in the web | cvebase.io